Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
n0tqu1tesane
May 7, 2003

She was rubbing her ass all over my hands. They don't just do that for everyone.
Grimey Drawer

mythicknight posted:

I have a giant Cisco Unity voicemail box I want to get voicemails out of. Problem: the unity web portal sucks rear end, and I'm talking about 100+ voicemails I'd have to manually click on to save as etc.

Is there an easier way to export or extract these wavs from Unity? (currently it is not tied to any AD or Exchange infrastructure)

Unity or Unity Connection? What version?

Adbot
ADBOT LOVES YOU

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...
Do you have voicemail to email set up? You should be able to forward them to an SMTP address as WAV files.

There are also a couple of programs that may do what you want that interface with CUC. Really the admin web GUI isn't that bad.

http://www.ciscounitytools.com/SiteList/AllDownloads/alldownloads.html

n0tqu1tesane
May 7, 2003

She was rubbing her ass all over my hands. They don't just do that for everyone.
Grimey Drawer

Bigass Moth posted:

Do you have voicemail to email set up? You should be able to forward them to an SMTP address as WAV files.

There are also a couple of programs that may do what you want that interface with CUC. Really the admin web GUI isn't that bad.

http://www.ciscounitytools.com/SiteList/AllDownloads/alldownloads.html



That one should do what they want.

mythicknight
Jan 28, 2009

my thick night

n0tqu1tesane posted:

Unity or Unity Connection? What version?

Cisco Unity Connection 10.5.2

Bigass Moth posted:

Do you have voicemail to email set up? You should be able to forward them to an SMTP address as WAV files.

There are also a couple of programs that may do what you want that interface with CUC. Really the admin web GUI isn't that bad.

http://www.ciscounitytools.com/SiteList/AllDownloads/alldownloads.html

No voicemail to email unfortunately. I think we do have voicemail notifications by email enabled though.

n0tqu1tesane posted:



That one should do what they want.

Thank you both, I'll try this out and see.

mythicknight
Jan 28, 2009

my thick night

Alright, I was able to get .eml files out of Unity Connection with .wav attachments to them with that tool. But the .wavs arent playing. I've tried WMP, VLC, foobar (which gave a "missing ACM codec" error), etc. I installed LAME, but I'm not sure what I'm still missing.

I also noticed the file size is different. If I pull the wav for an 8 second voicemail from the web inbox, its 130~KB and plays fine. If I pull the same wav from the eml file from the tool, its 8KB and trying to play it results in above errors.

God I hate voicemail.

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...
Maybe change the codec with Audacity? It sounds like something is going wrong with the supplemental tool. Are they downloading locally as .wav files?

mythicknight
Jan 28, 2009

my thick night

Bigass Moth posted:

Maybe change the codec with Audacity? It sounds like something is going wrong with the supplemental tool. Are they downloading locally as .wav files?

Audacity isn't recognizing it at all. I'm using the tool locally on my PC and getting the wav from the eml it saves here.

Partycat
Oct 25, 2004

If they are secured messages I don't believe you can archive them that way.

COBRAS backs up mail too but I don't know if you can get access to the contents through there.

Methanar
Sep 26, 2013

by the sex ghost
Hi it's me again.

More DDOS poo poo: How exactly do I increase my softIRQ capacity? I've found a cool new way that I die when attacked.

I've got some reasonably sized 4 core VMs that are doing NAT through IPtables. If I get poked juuust right the softIRQ load on these nat boxes go through the roof and then die, and stay dead until rebooted.

Part of the problem here is software side in that one of the two main uses for these nat boxes is logging out to an internet destination. Something gets hit (even if it's not the nat boxes themselves) and falls over, internally a fuckload of error logs get generated and forced through the nat box. SoftIRQ goes waay up, performance degrades, logs start to queue up faster than they can be emitted in the degraded state and after a few minutes the machine is dead. At this point external monitoring goes off saying the half DC is offline because nobody is able to send their heartbeats, internally accessible public IPs are no longer accessible, etc and generally the situation is unpleasant.

I've already doubled the number of nat boxes that are available to handle that type of sudden traffic flood, but as of a few days ago it has become apparent even that is not enough. I've considered the possibility of replacing these IPtables boxes with pfsense or something, but that's still a VM that needs to process connections, read rules in software and deal with VM CPU co-stops so I'm not convinced it would do any good. Buying a dedicated piece of hardware is not out of the question because this needs to stop.



I rage-blocked ICMP because that was one of the attack vectors and I'm getting tired of this poo poo. But then apparently this is a thing that exists https://blog.cloudflare.com/path-mtu-discovery-in-practice/ :(

Unrelated: does anyone have an sflow collector/visualizer they like? I set up Scrutinizer's free trial a few months ago and it's nice, but maybe there is something better

Methanar fucked around with this message at 21:55 on Jul 11, 2017

tortilla_chip
Jun 13, 2007

k-partite
You're probably hitting a state limit related to connection tracking.

Methanar posted:

More DDOS poo poo: How exactly do I increase my softIRQ capacity? I've found a cool new way that I die when attacked.

Unrelated: does anyone have an sflow collector/visualizer they like? I set up Scrutinizer's free trial a few months ago and it's nice, but maybe there is something better

The softIRQ spikes are probably the penalty for carrying state related to NAT/connection tracking. You can increase the table size and/or decrease the how long connections are tracked.

Kentik is nice for flows. You could also do pmacct and feed into grafana for cheap.

BelDin
Jan 29, 2001
Has anybody deployed Firepower in AWS? I'm struggling to wrap my head around it, especially from the lack of NAT abilities.

Basically wanting to have a public / private subnet and make a NGFWv the gateway between the two so all traffic goes through it. Do I need to make it a gateway between VPCs instead? How does SNAT work when I have to tie it to an AWS interface with a single IP?

pctD
Aug 25, 2009



Pillbug

Methanar posted:

Hi it's me again.

More DDOS poo poo: How exactly do I increase my softIRQ capacity? I've found a cool new way that I die when attacked.

I've got some reasonably sized 4 core VMs that are doing NAT through IPtables. If I get poked juuust right the softIRQ load on these nat boxes go through the roof and then die, and stay dead until rebooted.

Part of the problem here is software side in that one of the two main uses for these nat boxes is logging out to an internet destination. Something gets hit (even if it's not the nat boxes themselves) and falls over, internally a fuckload of error logs get generated and forced through the nat box. SoftIRQ goes waay up, performance degrades, logs start to queue up faster than they can be emitted in the degraded state and after a few minutes the machine is dead. At this point external monitoring goes off saying the half DC is offline because nobody is able to send their heartbeats, internally accessible public IPs are no longer accessible, etc and generally the situation is unpleasant.

I've already doubled the number of nat boxes that are available to handle that type of sudden traffic flood, but as of a few days ago it has become apparent even that is not enough. I've considered the possibility of replacing these IPtables boxes with pfsense or something, but that's still a VM that needs to process connections, read rules in software and deal with VM CPU co-stops so I'm not convinced it would do any good. Buying a dedicated piece of hardware is not out of the question because this needs to stop.



I rage-blocked ICMP because that was one of the attack vectors and I'm getting tired of this poo poo. But then apparently this is a thing that exists https://blog.cloudflare.com/path-mtu-discovery-in-practice/ :(

Unrelated: does anyone have an sflow collector/visualizer they like? I set up Scrutinizer's free trial a few months ago and it's nice, but maybe there is something better

I recently had a problem with this as well for DNAT but I solved it with stateless NAT outside iptables using traffic-control.

ate shit on live tv
Feb 15, 2004

by Azathoth
Yea Kentik is great, it's a bit pricey, but allows for a lot of data in a nice visual format. Sorting etc etc.

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
How pricy is pricy? Our network is about to be used in a public visible way by a company at the very pointy end of the F500 list on a retail device. We need to up our DDoS detection game.

Methanar
Sep 26, 2013

by the sex ghost
I talked to their sales people and while it was very nice, it didn't really give me what I was looking for, which was aiding making BGP decisions.

I got quoted at 10k per year minimum buy-in. I didn't get real numbers for how much per device/number of flows but that was still double what perpetual licenses of Scrutinizer would cost me.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
Kentik's pricing model is based on

* Number of routers sending flows
* Number of routers with full BGP feed to kentik
* Flows per second they process (you could adjust sampling rate on your side here)

It's a combination of all of those things. If you don't do the full BGP feeds it's a lot less useful. They may not even openly say it's an option to not have it, but I think it still is.

Re: "aiding in bgp decisions", that sounds like a bad idea, what are you trying to achieve?

We had an eng on our team buy Scrutinizer, we didn't get any use of it. Samplicator + NFSen + AS-STATS + other open sores stuff is much more useful IMO.

Methanar
Sep 26, 2013

by the sex ghost
Basically I don't know what I'm doing. A few days ago I set up another 10g link and did some rebalancing of how outbound traffic is sent to better spread it all across my now 5 links. It was less than successful for my first few attempts


My traffic and network has grown beyond the point where AS-path prepending is enough to get a proper spread across different carriers. Since I can't advertise blocks smaller than /24 I'm going to start needing to use different address space and advertise those address spaces differently. I'm going to need to be creative in which internal services get placed in which address spaces with what kind of route-maps to prefer which outbound paths. It's going to start becoming complicated and need better visibility than show int eth 1 and the different show ip bgp commands.

I was hoping that there would be a product that can keep some kind of clear visualization of all that. Maybe I find that one wan provider has a significantly worse RTT for a specific geographical location which would be negatively impacting all kinds of real-time traffic, but that's hard to troubleshoot because 1/3 of my internal services are being advertised out of HE while 2/3 are being advertised out of NTT. And who knows what's going to happen when I start to mess around with the BGP metrics in another 6 months when I set up more connections. Probably I'll try to send 20 gbps out of a 10g link again because I'm operating blind and have essentially no way of knowing what's going to happen when I set a prioritization of some sort until I do it live.

Methanar fucked around with this message at 20:19 on Jul 15, 2017

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
Use your providers BGP action communities to influence what they do with your prefixes.

https://onestep.net/communities/as7922/

https://us.ntt.net/support/policy/routing.cfm

I'd link to HE but lulz they're too cheap to do it (and their lovely brocade backbone probably doesn't support it)

You mentioned geography, you could send the community to prepend to some specific region via Comcast or NTT without prepending your entire ASN which may net you more success.

Also stop making GBS threads on the internet and send an aggregate route of your entire size if you can sincerely, my TCAM :)

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
w/r/t deagg, your t-cam is less important than my WAN spend.

Install as-stats and throw some sflow at it. You'll be out an hour or two and it'll help you immensely with knowing which far end networks are using which circuits on your network. And yeah, HE is fairly garbage tier. I could peer with them for free at all my sites, but tbh I don't want my packets on their network.

falz
Jan 29, 2005

01100110 01100001 01101100 01111010
Any Brocade users out there that have actually configured QOS on them? A previous network engineer bought several ICX6650's a few years back and we're stuck with those oddballs on our network. Anyhow, trying to find docs on default queue mappings on this platform.

It has 8 queues, defaults to 7/6 as strict, 5-0 with %. Trying to determine its default mappings for network control traffic, what if any default it uses for EF and AF and so on. It does let me remap them to whatever, but preferring to follow its defaults as best I can. Some docs for some platforms say 7 is Strict for stacking (which we dont use), which makes me guess 6 is strict for NC, but who knows!

PS I hate these things and I'm glad they're dead, but I probably need to keep these small handful for another year or so.

CrazyLittle
Sep 11, 2001





Clapping Larry
Welp Broadcomm's acquisition of Brocade will eventually solve all your problems. Apparently they're killing off all of their product lines, including the last bits of Vyatta

Prescription Combs
Apr 20, 2005
   6

CrazyLittle posted:

Welp Broadcomm's acquisition of Brocade will eventually solve all your problems. Apparently they're killing off all of their product lines, including the last bits of Vyatta

This makes me beyond happy. I have to deal with their lovely ServerIron ADX's at work all the time. Constant hardware failures and dumbass software bugs.

Thanks Ants
May 21, 2004

#essereFerrari


Which bits of Brocade went over to Extreme? I thought Vyatta was included in that.

Proteus Jones
Feb 28, 2013



Thanks Ants posted:

Which bits of Brocade went over to Extreme? I thought Vyatta was included in that.

It was all the data center products, but I can't see anywhere where it lists specific products.


E: best I could find

http://www.extremenetworks.com/extreme-networks-brocade-acquisition-faq/

quote:

What exactly is Extreme Networks acquiring?

A: Extreme will acquire all of the assets of Brocade’s recently refreshed high-end data center networking business including data center switching (VDX) and routing (MLX), as well as a new converged switching/routing product line (SLX), in addition to world-class automation and network application visibility software. Brocade’s portfolio enables Extreme to compete in larger enterprise data center opportunities and opens new sales opportunities for the campus/edge network from Brocade’s existing large enterprise data center customers.

1000101
May 14, 2003

BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY BIRTHDAY FRUITCAKE!

Proteus Jones posted:

It was all the data center products, but I can't see anywhere where it lists specific products.


E: best I could find

http://www.extremenetworks.com/extreme-networks-brocade-acquisition-faq/

http://about.att.com/story/att_to_acquire_vyatta_software_technology_from_brocade.html

Vyatta went to AT&T.

jwh
Jun 12, 2002

Prescription Combs posted:

This makes me beyond happy. I have to deal with their lovely ServerIron ADX's at work all the time. Constant hardware failures and dumbass software bugs.

I think the ServerIrons go all the way back to Foundry Networks days.

Jedi425
Dec 6, 2002

THOU ART THEE ART THOU STICK YOUR HAND IN THE TV DO IT DO IT DO IT

Fun facts about the ADX:

-Before 12.5 firmware, High Availability setups didn't sync the full configuration. Notably, you had to manually copy SSL certs/keys/profiles to both units. If your co-worker wasn't paying attention when he or she added an SSL profile to the primary unit, you'd end up with a lot of broken sites in a failover scenario.

-When TLS rollout became a Big Deal after Heartbleed and all that mess, it took Brocade something like a year (?) to release firmware that supported higher-end ciphers. This is because (I was told) the ADX is built on some kind of godawful PowerPC chip, and they literally could not find anyone who knew how to code on it anymore.

-Speaking of bad chips, the SSL accelerator on the ADX is so lovely that the loving thing could barely do upward of like 200 TPS or some god awful number when they first rolled out the new EC ciphers. They had to add code so that new ciphers used the regular processor cores in addition to the SSL processor to get decent TPS out of it.


Basically if the ADX is dead, I will dance on its' grave.

CrazyLittle
Sep 11, 2001





Clapping Larry

rip

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Methanar posted:

Basically I don't know what I'm doing. A few days ago I set up another 10g link and did some rebalancing of how outbound traffic is sent to better spread it all across my now 5 links. It was less than successful for my first few attempts


My traffic and network has grown beyond the point where AS-path prepending is enough to get a proper spread across different carriers. Since I can't advertise blocks smaller than /24 I'm going to start needing to use different address space and advertise those address spaces differently. I'm going to need to be creative in which internal services get placed in which address spaces with what kind of route-maps to prefer which outbound paths. It's going to start becoming complicated and need better visibility than show int eth 1 and the different show ip bgp commands.

I was hoping that there would be a product that can keep some kind of clear visualization of all that. Maybe I find that one wan provider has a significantly worse RTT for a specific geographical location which would be negatively impacting all kinds of real-time traffic, but that's hard to troubleshoot because 1/3 of my internal services are being advertised out of HE while 2/3 are being advertised out of NTT. And who knows what's going to happen when I start to mess around with the BGP metrics in another 6 months when I set up more connections. Probably I'll try to send 20 gbps out of a 10g link again because I'm operating blind and have essentially no way of knowing what's going to happen when I set a prioritization of some sort until I do it live.

What sort of real-time traffic are you sending that's filling multiple 10G links?

Methanar
Sep 26, 2013

by the sex ghost
Lots of video and webRTC

Pile Of Garbage
May 28, 2007



falz posted:

PS I hate these things and I'm glad they're dead, but I probably need to keep these small handful for another year or so.

I really liked Brocade FC switches and MPRs, nice GUI and CLI, never had any significant issues outside of one or two dodgy SFPs.

Never used their IP stuff though so yeah.

psydude
Apr 1, 2008

gently caress Vyatta.

Thanks Ants
May 21, 2004

#essereFerrari


Silkworms were good

falz
Jan 29, 2005

01100110 01100001 01101100 01111010

cheese-cube posted:

I really liked Brocade FC switches and MPRs, nice GUI and CLI, never had any significant issues outside of one or two dodgy SFPs.

Never used their IP stuff though so yeah.

Pretty much all of their stuff is acquisitions and they slapped together an OS that's 90% similar from a CLI perspective but they only work 50% the same.

Anyhow, somebrocadeguy came out of the woodwork and answered my question in foundry-nsp if anyone else was curious. Why this poo poo doesn't seem to be published in their standard docs I do not know.

https://puck.nether.net/pipermail/foundry-nsp/2017-July/009794.html

Pile Of Garbage
May 28, 2007



Actually reading that kind of makes sense with my experience which was via Brocade gear re-branded for IBM. They (Brocade) published some extremely specific and relevant errata regarding their products only via IBM's website. For example, port fillword settings for 8Gb FC compatibility with IBM SVC kit (Including Storwize V7000). Also the feature licensing for Brocade MPRs was obscene. At one point I caught out our VAR for loving up SFP and port licenses but copping that cost still didn't bite into their (IBMs) margin.

Still, I really miss working with FC :(

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
Brocade for SPs is pretty much dead. They removed our account team and didn't even bother to tell us. We asked our SE to push a TAC case for us and he mentioned that he was off our account. We were a fairly decent install base for them. Cisco isn't even paying out for replacing Brocade equipment this FY.

PO went to Cisco last week for 10x ASR9ks and an assortment of other things.

mythicknight
Jan 28, 2009

my thick night

Partycat posted:

If they are secured messages I don't believe you can archive them that way.

COBRAS backs up mail too but I don't know if you can get access to the contents through there.

Nvm, it was working perfectly.

mythicknight fucked around with this message at 15:14 on Jul 28, 2017

ate shit on live tv
Feb 15, 2004

by Azathoth
A neat thing I came across in JunOS.

me@core1a> show version and haiku
Hostname: core1a
Model: mx5-t
Junos: 13.3R8.7
JUNOS Base OS boot [13.3R8.7]
JUNOS Base OS Software Suite [13.3R8.7]
JUNOS Kernel Software Suite [13.3R8.7]
JUNOS Crypto Software Suite [13.3R8.7]
JUNOS Packet Forwarding Engine Support (MX80) [13.3R8.7]
JUNOS Online Documentation [13.3R8.7]
JUNOS Services Application Level Gateways [13.3R8.7]
JUNOS Services Jflow Container package [13.3R8.7]
JUNOS Services Stateful Firewall [13.3R8.7]
JUNOS Services NAT [13.3R8.7]
JUNOS Services RPM [13.3R8.7]
JUNOS Services Crypto [13.3R8.7]
JUNOS Services SSL [13.3R8.7]
JUNOS Services IPSec [13.3R8.7]
JUNOS Routing Software Suite [13.3R8.7]


One fish in the tank
Will he last another week
Poor little mutant

Methanar
Sep 26, 2013

by the sex ghost
I'm going to 1-up you with Arista

code:
localhost>show chickens
Farm utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0%
 DID S  Ty       DC  Runtime(ms)      Rides   Poops       Hay DKY Donkeyname
   1 M  sp 602F3AF0            0       1627       0 2600/3000   0 Eeyore
   2 F  we 60C5BE00            4        136      29 5572/6000   0 Tingaleo
   3 F  st 602D90F8         1676        837    2002 5740/6000   0 Daisy
   4 M  we 602D08F8            0          1       0 5568/6000   0 Wonky Don
   5 F  we 602DF0E8            0          1       0 5592/6000   0 Dakota
   6 M  st 60251E38            0          2       0 5560/6000   0 Superdonkey
   7 M  we 600D4940            0          2       0 5568/6000   0 Cookie Dough
   8 F  we 6034B718            0          1       0 2584/3000   0 Sandy
   9 F  we 603FA3C8            0          1       0 5612/6000   0 Kekie
  10 M  we 603FA1A0            0       8124       0 5488/6000   0 Shrek
  11 M  we 603FA220            0          9       0 4884/6000   0 Billy Joe-Bob
  12 U  we 60406818          124       2003      61 5300/6000   0 Smokey
  13 M  we 60581638            0          1       0 5760/6000   0 Snickers
  14 M  we 605E3D00            0          2       0 5564/6000   0 D.K.
  15 M  we 605FC6B8            0          2       011568/12000  0 Hee-Haw

                                  /\          /\
                                 ( \\        // )
                                  \ \\      // /
                                   \_\\||||//_/
                                    \/ _  _ \
                                   \/|(o)(O)|
                                  \/ |      |
              ___________________\/  \      /
             //                //     |____|       Cluck cluck cluck!
            //                ||     /      \
           //|                \|     \ 0  0 /
          // \       )         V    / \____/
         //   \     /        (     /
        ""     \   /_________|  |_/
               /  /\   /     |  ||
              /  / /  /      \  ||
              | |  | |        | ||
              | |  | |        | ||
              |_|  |_|        |_||
               \_\  \_\        \_\\ 

Adbot
ADBOT LOVES YOU

Moey
Oct 22, 2010

I LIKE TO MOVE IT

ate poo poo on live tv posted:

A neat thing I came across in JunOS.


One fish in the tank
Will he last another week
Poor little mutant


Well this just made my day.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply